FireGen Report
| Info | Value |
|---|---|
| Log profile | Log profile fortigate |
| Analyzed log(s) |
F:\Logs\Fortigate\2006-10-31-Fortigate.txt (86.00 MB) |
| Firewall type | Fortigate |
| Analysis interval | All entries in the specified log |
Firewalls
| No | Firewall | Connections | Traffic (MB) | Denials | Warnings | URLs | 1 | FGT8002604401800 | 146,452 | 2,701.79 | 19,575 | 587 | 00 |
|---|
Message types
| No | Code | Message sample | Count | 2 | 0021010001 | type=traffic subtype=allowed pri=notice vd=root SN=458307 duration=236 user=N/A group=N/A policyid=49 proto=6 service=443/tcp app_type=N/A status=accept src=69.50.48.72 srcname=69.50.48.72 dst=69.49.150.134 dstname=69.49.150.134 src_int=external dst_int=dmz sent=11500 rcvd=71916 sent_pkt=86 rcvd_pkt=132 src_port=2463 dst_port=443 vpn=N/A tran_ip=0.0.0.0 tran_port=0 dir_disp=org tran_disp=noop | 146,452 | 3 | 0022013001 | type=traffic subtype=violation pri=warning vd=root SN=458728 duration=0 user=N/A group=N/A policyid=61 proto=6 service=80/tcp app_type=N/A status=deny src=10.1.1.148 srcname=10.1.1.148 dst=205.243.60.43 dstname=205.243.60.43 src_int=internal dst_int=external sent=0 rcvd=0 src_port=1469 dst_port=80 vpn=N/A tran_ip=0.0.0.0 tran_port=0 | 19,454 | 4 | 0101023002 | type=event subtype=ipsec pri=notice vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=24.97.162.254 rem_port=500 out_if=external vpn_tunnel=SysEng-VPN cookies=999832fa9e4c7e8a/951ec852745dd5fb action=negotiate status=success msg="Responder: tunnel 24.97.162.254, transform=ESP_3DES, HMAC_SHA1" | 154 | 5 | 0101023003 | type=event subtype=ipsec pri=error vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=63.77.242.162 rem_port=500 out_if=external vpn_tunnel=SCC-Primary cookies=1349866be05ab9e6/669e8b95aeea00e1 action=negotiate status=negotiate_error msg="Negotiate SA Error: Peer's id payloads do not match local policy." | 556 | 6 | 0101023004 | type=event subtype=ipsec pri=notice vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=24.97.162.254 rem_port=500 out_if=external vpn_tunnel=SysEng-VPN cookies=999832fa9e4c7e8a/951ec852745dd5fb action=negotiate init=remote mode=quick stage=2 dir=inbound status=success msg="Responder: parsed 24.97.162.254 quick mode message #2 (DONE)" | 1,909 | 7 | 0101023006 | type=event subtype=ipsec pri=notice vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=24.97.162.254 rem_port=500 out_if=external vpn_tunnel=SysEng-VPN cookies=999832fa9e4c7e8a/951ec852745dd5fb action=install_sa in_spi=7b4e35fb out_spi=5d920960 msg="Responder: tunnel 69.49.150.10/24.97.162.254 install ipsec sa" | 154 | 8 | 0101023007 | type=event subtype=ipsec pri=notice vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=63.77.242.162 rem_port=500 out_if=external vpn_tunnel=SCC-Primary cookies=f626dde421e12e2c/58f225bcf785c2b0 action=delete_phase1_sa msg="Deleted an Isakmp SA on the tunnel to 63.77.242.162:500" | 346 | 9 | 0101023008 | type=event subtype=ipsec pri=notice vd=root loc_ip=69.49.150.10 loc_port=500 rem_ip=63.77.242.174 rem_port=500 out_if=? vpn_tunnel=FGh_FtiLog1 cookies=1d08bbf24c2a6a15/399b9241a7e2ab4f action=delete_ipsec_sa enc_spi=4be2f833 dec_spi=f7354e7b msg="Deleted an IPsec SA on the tunnel to 63.77.242.174:500" | 152 | 10 | 0104032006 | type=event subtype=admin pri=information vd=root user="admin" ui=GUI(63.75.200.25) action=login status=success reason=none msg="User admin login successfully from GUI(63.75.200.25)" | 08 | 11 | 0104032007 | type=event subtype=admin pri=information vd=root user="nsnm-ro" ui=ssh(10.1.1.252) action=logout status=success reason=exit msg="User nsnm-ro Logs out from ssh(10.1.1.252)" | 02 | 12 | 0104032105 | type=event subtype=admin pri=notice vd=root status=update virdb=yes idsdb=yes libav=yes aven=yes imap=yes smtp=yes pop3=yes http=yes ftp=yes fcni=yes fdni=yes idsmn=yes idssn=yes msg="Fortigate push update virdb(6.779) idsdb(2.328) aven(2.002) idsen(1.035) from 206.191.24.179:443" | 17 | 13 | 0211060000 | type=virus subtype=infected pri=notice vd=root serial=449907 user="N/A" group="N/A" src=10.1.1.9 dst=66.98.238.101 src_int=internal dst_int=external service=http status=passthrough file="kaspersky.zip" virus="Suspicious" url="http://update.gfisoftware.com/avx/kaspersky.zip" ref="http://www.fortinet.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=quickSearchDirectly&virusName=Suspicious" msg="The file kaspersky.zip is infected with Suspicious." | 23 | 14 | 0419070000 | type=ips subtype=signature pri=alert vd=root serial=387540 attack_id=107347979 severity=critical src=10.1.1.15 dst=69.49.150.146 src_port=80 dst_port=31241 src_int=internal dst_int=port2 status=detected proto=6 service=31241/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/ID107347979" msg="http_decoder: request_smuggling, aggregated 4 times [Reference: http://www.fortinet.com/ids/ID107347979]" | 68 |
|---|
Firewall: FGT8002604401800
FGT8002604401800 - Traffic and denials per hour




| Hour | Traffic (MB) | % | Connections | % | Denials | % | |
|---|---|---|---|---|---|---|---|
| 00-01 | 51.00 | 1.91 | 4,750 | 2.86 | 485 | 2.48 | |
| 01-02 | 11.00 | 0.43 | 3,249 | 1.96 | 637 | 3.25 | |
| 02-03 | 31.00 | 1.15 | 3,348 | 2.02 | 644 | 3.29 | |
| 03-04 | 30.00 | 1.13 | 3,224 | 1.94 | 619 | 3.16 | |
| 04-05 | 34.00 | 1.28 | 3,202 | 1.93 | 481 | 2.46 | |
| 05-06 | 44.00 | 1.66 | 3,577 | 2.15 | 603 | 3.08 | |
| 06-07 | 99.00 | 3.69 | 3,897 | 2.35 | 505 | 2.58 | |
| 07-08 | 196.00 | 7.27 | 7,825 | 4.71 | 634 | 3.24 | |
| 08-09 | 216.00 | 8.03 | 11,991 | 7.22 | 541 | 2.76 | |
| 09-10 | 215.00 | 7.97 | 12,019 | 7.24 | 1,022 | 5.22 | |
| 10-11 | 195.00 | 7.22 | 10,744 | 6.47 | 793 | 4.05 | |
| 11-12 | 212.00 | 7.86 | 12,780 | 7.70 | 709 | 3.62 | |
| 12-13 | 177.00 | 6.57 | 10,422 | 6.28 | 599 | 3.06 | |
| 13-14 | 214.00 | 7.93 | 11,927 | 7.18 | 667 | 3.41 | |
| 14-15 | 179.00 | 6.66 | 7,957 | 4.79 | 695 | 3.55 | |
| 15-16 | 187.00 | 6.92 | 12,317 | 7.42 | 735 | 3.75 | |
| 16-17 | 141.00 | 5.23 | 9,410 | 5.67 | 643 | 3.28 | |
| 17-18 | 76.00 | 2.82 | 4,643 | 2.80 | 641 | 3.27 | |
| 18-19 | 74.00 | 2.76 | 3,661 | 2.21 | 611 | 3.12 | |
| 19-20 | 74.00 | 2.75 | 4,738 | 2.85 | 1,636 | 8.36 | |
| 20-21 | 56.00 | 2.08 | 5,604 | 3.38 | 2,042 | 10.43 | !!! |
| 21-22 | 66.00 | 2.46 | 4,923 | 2.97 | 1,558 | 7.96 | |
| 22-23 | 58.00 | 2.18 | 3,802 | 2.29 | 948 | 4.84 | |
| 23-24 | 54.00 | 2.03 | 6,017 | 3.62 | 1,127 | 5.76 |
FGT8002604401800 - Interfaces
| No | Interfaces | Connections | MB | % | Denials | Warnings |
|---|---|---|---|---|---|---|
| 1 | dmz to external | 1,502 | 04.69 | 00.17 | 00 | 00 |
| 2 | dmz to internal | 4,942 | 54.90 | 02.03 | 00 | 00 |
| 3 | external to dmz | 10,955 | 1,146.55 | 42.44 | 00 | 00 |
| 4 | external to internal | 10,713 | 38.14 | 01.41 | 00 | 00 |
| 5 | external to port2 | 99 | 11.52 | 00.43 | 00 | 00 |
| 6 | internal to dmz | 219 | 25.89 | 00.96 | 00 | 00 |
| 7 | internal to external | 113,449 | 1,321.39 | 48.91 | 16,142 | 23 |
| 8 | internal to port1 | 947 | 13.55 | 00.50 | 00 | 00 |
| 9 | internal to port2 | 04 | 14.80 | 00.55 | 96 | 00 |
| 10 | N/A to external | 1,601 | 18.83 | 00.70 | 1,857 | 00 |
| 11 | port1 to external | 36 | 17.52 | 00.65 | 00 | 00 |
| 12 | port2 to internal | 1,985 | 33.99 | 01.26 | 1,480 | 00 |
| 13 | Not specified | 00 | 00.00 | 00.00 | 00 | 08 |
| 14 | n/a to external | 00 | 00.00 | 00.00 | 00 | 556 |
| 15 | if to | 00 | 00.00 | 00.00 | 00 | 00 |
| 16 | if to external | 00 | 00.00 | 00.00 | 00 | 00 |
| Total | 146,452 | 2,701.79 | 19,575 | 587 |
Firewall: FGT8002604401800 - Interfaces: dmz to external - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.138 | 2,267,865 | 46.07 | |
| 2 | 69.49.150.133 | 1,346,350 | 27.35 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 3 | 69.49.150.135 | 1,308,614 | 26.58 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 67.141.56.4 | 2,644,678 | 53.72 | |
| 2 | 63.75.200.11 | 630,934 | 12.82 | |
| 3 | 209.222.136.4 | 517,120 | 10.50 | |
| 4 | 206.191.24.179 | 371,938 | 7.56 | |
| 5 | 63.75.200.20 | 314,003 | 6.38 | |
| 6 | 63.77.242.174 | 230,296 | 4.68 | |
| 7 | 65.61.202.131 | 199,420 | 4.05 | |
| 8 | 204.34.198.40 | 14,440 | 0.29 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 69.49.150.133 | TCP/443 - ssl-https | 476 | 1,346,350 | 27.35 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 2 | 69.49.150.135 | TCP/443 - ssl-https | 457 | 1,298,328 | 26.37 | |
| 3 | 69.49.150.138 | TCP/443 - ssl-https | 26 | 1,088,478 | 22.11 | |
| 4 | 69.49.150.138 | UDP/514 - syslog | 212 | 630,934 | 12.82 | |
| 5 | 69.49.150.138 | UDP/162 - snmp-trap | 87 | 303,717 | 6.17 | |
| 6 | 69.49.150.138 | UDP/500 - ipsec | 213 | 230,296 | 4.68 | |
| 7 | 69.49.150.138 | UDP/123 - ntp | 24 | 14,440 | 0.29 | |
| 8 | 69.49.150.135 | UDP/162 - snmp-trap | 07 | 10,286 | 0.21 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.133 | 67.141.56.4 | TCP/443 - ssl-https | 476 | 1,346,350 | 27.35 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 2 | 69.49.150.135 | 67.141.56.4 | TCP/443 - ssl-https | 457 | 1,298,328 | 26.37 | |
| 3 | 69.49.150.138 | 63.75.200.11 | UDP/514 - syslog | 212 | 630,934 | 12.82 | |
| 4 | 69.49.150.138 | 209.222.136.4 | TCP/443 - ssl-https | 11 | 517,120 | 10.50 | |
| 5 | 69.49.150.138 | 206.191.24.179 | TCP/443 - ssl-https | 09 | 371,938 | 7.56 | |
| 6 | 69.49.150.138 | 63.75.200.20 | UDP/162 - snmp-trap | 87 | 303,717 | 6.17 | |
| 7 | 69.49.150.138 | 63.77.242.174 | UDP/500 - ipsec | 213 | 230,296 | 4.68 | |
| 8 | 69.49.150.138 | 65.61.202.131 | TCP/443 - ssl-https | 06 | 199,420 | 4.05 | |
| 9 | 69.49.150.138 | 204.34.198.40 | UDP/123 - ntp | 24 | 14,440 | 0.29 | |
| 10 | 69.49.150.135 | 63.75.200.20 | UDP/162 - snmp-trap | 07 | 10,286 | 0.21 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 959 | 3,733,156 | 75.83 | |
| 2 | UDP/514 - syslog | 212 | 630,934 | 12.82 | |
| 3 | UDP/162 - snmp-trap | 94 | 314,003 | 6.38 | |
| 4 | UDP/500 - ipsec | 213 | 230,296 | 4.68 | |
| 5 | UDP/123 - ntp | 24 | 14,440 | 0.29 |

Firewall: FGT8002604401800 - Interfaces: dmz to internal - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.133 | 38,395,335 | 66.69 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 2 | 69.49.150.135 | 19,176,723 | 33.31 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.1.25 | 38,105,313 | 66.19 | |
| 2 | 10.1.1.12 | 10,845,323 | 18.84 | |
| 3 | 10.1.1.49 | 8,615,423 | 14.96 | |
| 4 | 10.1.1.27 | 5,999 | 0.01 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 69.49.150.133 | UDP/514 - syslog | 3,613 | 19,429,942 | 33.75 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 2 | 69.49.150.135 | TCP/21000 | 230 | 18,029,013 | 31.32 | |
| 3 | 69.49.150.133 | TCP/21000 | 231 | 17,777,769 | 30.88 | |
| 4 | 69.49.150.133 | TCP/22000 | 374 | 1,154,748 | 2.01 | |
| 5 | 69.49.150.135 | TCP/22000 | 347 | 1,036,510 | 1.80 | |
| 6 | 69.49.150.135 | TCP/24001 | 10 | 60,630 | 0.11 | |
| 7 | 69.49.150.135 | UDP/514 - syslog | 68 | 26,916 | 0.05 | |
| 8 | 69.49.150.133 | TCP/24001 | 06 | 25,022 | 0.04 | |
| 9 | 69.49.150.135 | TCP/24000 | 21 | 13,767 | 0.02 | |
| 10 | 69.49.150.133 | TCP/24000 | 12 | 7,854 | 0.01 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.135 | 10.1.1.25 | TCP/21000 | 230 | 18,029,013 | 31.32 | |
| 2 | 69.49.150.133 | 10.1.1.25 | TCP/21000 | 231 | 17,777,769 | 30.88 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 3 | 69.49.150.133 | 10.1.1.12 | UDP/514 - syslog | 2,020 | 10,827,977 | 18.81 | |
| 4 | 69.49.150.133 | 10.1.1.49 | UDP/514 - syslog | 1,593 | 8,601,965 | 14.94 | |
| 5 | 69.49.150.133 | 10.1.1.25 | TCP/22000 | 374 | 1,154,748 | 2.01 | |
| 6 | 69.49.150.135 | 10.1.1.25 | TCP/22000 | 347 | 1,036,510 | 1.80 | |
| 7 | 69.49.150.135 | 10.1.1.25 | TCP/24001 | 10 | 60,630 | 0.11 | |
| 8 | 69.49.150.133 | 10.1.1.25 | TCP/24001 | 06 | 25,022 | 0.04 | |
| 9 | 69.49.150.135 | 10.1.1.25 | TCP/24000 | 21 | 13,767 | 0.02 | |
| 10 | 69.49.150.135 | 10.1.1.12 | UDP/514 - syslog | 34 | 13,458 | 0.02 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/21000 | 461 | 35,806,782 | 62.19 | |
| 2 | UDP/514 - syslog | 3,681 | 19,456,858 | 33.80 | |
| 3 | TCP/22000 | 721 | 2,191,258 | 3.81 | |
| 4 | TCP/24001 | 16 | 85,652 | 0.15 | |
| 5 | TCP/24000 | 33 | 21,621 | 0.04 | |
| 6 | TCP/13000 | 03 | 5,999 | 0.01 | |
| 7 | TCP/2967 | 27 | 3,888 | 0.01 |

Firewall: FGT8002604401800 - Interfaces: external to dmz - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 64.222.230.206 | 28,194,077 | 2.35 | |
| 2 | 63.75.200.9 | 13,654,884 | 1.14 | |
| 3 | 204.10.46.254 | 12,671,655 | 1.05 | |
| 4 | 216.220.240.250 | 9,388,487 | 0.78 | |
| 5 | 216.195.223.226 | 7,760,308 | 0.65 | |
| 6 | 207.190.217.114 | 7,433,603 | 0.62 | |
| 7 | 24.93.148.189 | 6,302,215 | 0.52 | |
| 8 | 24.97.228.90 | 6,243,467 | 0.52 | |
| 9 | 216.204.161.138 | 5,935,533 | 0.49 | |
| 10 | 65.217.160.194 | 4,841,056 | 0.40 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.134 | 1,184,867,996 | 98.55 | |
| 2 | 69.49.150.135 | 15,508,675 | 1.29 | |
| 3 | 69.49.150.133 | 1,394,400 | 0.12 | 3 denials recorded on 4/4/2006 12:10:19 AM |
| 4 | 69.49.150.138 | 414,942 | 0.03 | |
| 5 | 69.49.150.141 | 57,051 | 0.00 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 64.222.230.206 | TCP/443 - ssl-https | 129 | 28,194,077 | 2.35 | |
| 2 | 63.75.200.9 | TCP/902 | 02 | 13,654,884 | 1.14 | |
| 3 | 204.10.46.254 | TCP/443 - ssl-https | 93 | 12,671,655 | 1.05 | |
| 4 | 216.220.240.250 | TCP/443 - ssl-https | 70 | 9,388,487 | 0.78 | |
| 5 | 216.195.223.226 | TCP/443 - ssl-https | 44 | 7,760,308 | 0.65 | |
| 6 | 207.190.217.114 | TCP/443 - ssl-https | 31 | 7,433,603 | 0.62 | |
| 7 | 24.93.148.189 | TCP/443 - ssl-https | 25 | 6,302,215 | 0.52 | |
| 8 | 24.97.228.90 | TCP/443 - ssl-https | 12 | 6,243,467 | 0.52 | |
| 9 | 216.204.161.138 | TCP/443 - ssl-https | 20 | 5,935,533 | 0.49 | |
| 10 | 65.217.160.194 | TCP/443 - ssl-https | 22 | 4,841,056 | 0.40 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 64.222.230.206 | 69.49.150.134 | TCP/443 - ssl-https | 129 | 28,194,077 | 2.35 | |
| 2 | 63.75.200.9 | 69.49.150.135 | TCP/902 | 02 | 13,654,884 | 1.14 | |
| 3 | 204.10.46.254 | 69.49.150.134 | TCP/443 - ssl-https | 93 | 12,671,655 | 1.05 | |
| 4 | 216.220.240.250 | 69.49.150.134 | TCP/443 - ssl-https | 70 | 9,388,487 | 0.78 | |
| 5 | 216.195.223.226 | 69.49.150.134 | TCP/443 - ssl-https | 44 | 7,760,308 | 0.65 | |
| 6 | 207.190.217.114 | 69.49.150.134 | TCP/443 - ssl-https | 31 | 7,433,603 | 0.62 | |
| 7 | 24.93.148.189 | 69.49.150.134 | TCP/443 - ssl-https | 25 | 6,302,215 | 0.52 | |
| 8 | 24.97.228.90 | 69.49.150.134 | TCP/443 - ssl-https | 12 | 6,243,467 | 0.52 | |
| 9 | 216.204.161.138 | 69.49.150.134 | TCP/443 - ssl-https | 20 | 5,935,533 | 0.49 | |
| 10 | 65.217.160.194 | 69.49.150.134 | TCP/443 - ssl-https | 22 | 4,841,056 | 0.40 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 9,399 | 1,185,149,734 | 98.58 | |
| 2 | TCP/902 | 02 | 13,654,884 | 1.14 | |
| 3 | TCP/2998 | 110 | 3,136,704 | 0.26 | |
| 4 | ICMP/8 - ping | 1,437 | 284,928 | 0.02 | |
| 5 | UDP/161 - snmp | 07 | 16,814 | 0.00 |

Firewall: FGT8002604401800 - Interfaces: external to internal - Go to top
Top 10 sources
Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.200.201.17 | 39,997,836 | 100.00 |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 172.16.229.1 | 13,110,303 | 32.78 | |
| 2 | 172.16.229.19 | 2,873,569 | 7.18 | |
| 3 | 172.16.229.4 | 2,857,099 | 7.14 | |
| 4 | 172.16.229.9 | 2,449,248 | 6.12 | |
| 5 | 172.16.229.15 | 1,753,023 | 4.38 | |
| 6 | 172.16.229.14 | 1,121,791 | 2.80 | |
| 7 | 172.16.229.10 | 1,115,712 | 2.79 | |
| 8 | 172.16.229.20 | 1,114,536 | 2.79 | |
| 9 | 172.16.229.17 | 1,103,516 | 2.76 | |
| 10 | 172.16.229.5 | 1,102,899 | 2.76 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.200.201.17 | UDP/161 - snmp | 4,374 | 38,386,960 | 95.97 | |
| 2 | 10.200.201.17 | ICMP/8 - ping | 6,317 | 1,200,420 | 3.00 | |
| 3 | 10.200.201.17 | TCP/23 - telnet | 22 | 410,456 | 1.03 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.200.201.17 | 172.16.229.1 | UDP/161 - snmp | 181 | 13,026,510 | 32.57 | |
| 2 | 10.200.201.17 | 172.16.229.19 | UDP/161 - snmp | 202 | 2,799,522 | 7.00 | |
| 3 | 10.200.201.17 | 172.16.229.4 | UDP/161 - snmp | 207 | 2,786,624 | 6.97 | |
| 4 | 10.200.201.17 | 172.16.229.9 | UDP/161 - snmp | 195 | 2,377,017 | 5.94 | |
| 5 | 10.200.201.17 | 172.16.229.15 | UDP/161 - snmp | 200 | 1,672,320 | 4.18 | |
| 6 | 10.200.201.17 | 172.16.229.14 | UDP/161 - snmp | 199 | 1,049,529 | 2.62 | |
| 7 | 10.200.201.17 | 172.16.229.20 | UDP/161 - snmp | 201 | 1,043,080 | 2.61 | |
| 8 | 10.200.201.17 | 172.16.229.10 | UDP/161 - snmp | 201 | 1,036,088 | 2.59 | |
| 9 | 10.200.201.17 | 172.16.229.5 | UDP/161 - snmp | 200 | 1,031,998 | 2.58 | |
| 10 | 10.200.201.17 | 172.16.229.17 | UDP/161 - snmp | 163 | 1,031,958 | 2.58 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/161 - snmp | 4,374 | 38,386,960 | 95.97 | |
| 2 | ICMP/8 - ping | 6,317 | 1,200,420 | 3.00 | |
| 3 | TCP/23 - telnet | 22 | 410,456 | 1.03 |

Firewall: FGT8002604401800 - Interfaces: external to port2 - Go to top
Top 10 sources

Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 24.39.14.254 | 10,933,249 | 90.52 | |
| 2 | 72.224.140.179 | 1,000,908 | 8.29 | |
| 3 | 8.10.222.213 | 61,314 | 0.51 | |
| 4 | 70.220.243.27 | 23,702 | 0.20 | |
| 5 | 75.195.108.127 | 19,768 | 0.16 | |
| 6 | 75.195.20.47 | 15,079 | 0.12 | |
| 7 | 8.8.93.30 | 14,248 | 0.12 | |
| 8 | 75.194.33.225 | 9,973 | 0.08 | |
| 9 | 69.39.70.231 | 595 | 0.00 | 3 denials recorded on 10/31/2006 6:30:40 PM |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.146 | 12,078,836 | 100.00 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 24.39.14.254 | TCP/443 - ssl-https | 73 | 10,933,249 | 90.52 | |
| 2 | 72.224.140.179 | TCP/443 - ssl-https | 11 | 1,000,908 | 8.29 | |
| 3 | 8.10.222.213 | TCP/443 - ssl-https | 05 | 61,314 | 0.51 | |
| 4 | 70.220.243.27 | TCP/443 - ssl-https | 02 | 23,702 | 0.20 | |
| 5 | 75.195.108.127 | TCP/443 - ssl-https | 02 | 19,768 | 0.16 | |
| 6 | 75.195.20.47 | TCP/443 - ssl-https | 02 | 15,079 | 0.12 | |
| 7 | 8.8.93.30 | TCP/443 - ssl-https | 01 | 14,248 | 0.12 | |
| 8 | 75.194.33.225 | TCP/443 - ssl-https | 01 | 9,973 | 0.08 | |
| 9 | 69.39.70.231 | TCP/443 - ssl-https | 02 | 595 | 0.00 | 3 denials recorded on 10/31/2006 6:30:40 PM |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 24.39.14.254 | 69.49.150.146 | TCP/443 - ssl-https | 73 | 10,933,249 | 90.52 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | 72.224.140.179 | 69.49.150.146 | TCP/443 - ssl-https | 11 | 1,000,908 | 8.29 | |
| 3 | 8.10.222.213 | 69.49.150.146 | TCP/443 - ssl-https | 05 | 61,314 | 0.51 | |
| 4 | 70.220.243.27 | 69.49.150.146 | TCP/443 - ssl-https | 02 | 23,702 | 0.20 | |
| 5 | 75.195.108.127 | 69.49.150.146 | TCP/443 - ssl-https | 02 | 19,768 | 0.16 | |
| 6 | 75.195.20.47 | 69.49.150.146 | TCP/443 - ssl-https | 02 | 15,079 | 0.12 | |
| 7 | 8.8.93.30 | 69.49.150.146 | TCP/443 - ssl-https | 01 | 14,248 | 0.12 | |
| 8 | 75.194.33.225 | 69.49.150.146 | TCP/443 - ssl-https | 01 | 9,973 | 0.08 | |
| 9 | 69.39.70.231 | 69.49.150.146 | TCP/443 - ssl-https | 02 | 595 | 0.00 | 3 denials recorded on 10/31/2006 6:30:40 PM |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 99 | 12,078,836 | 100.00 |
Firewall: FGT8002604401800 - Interfaces: internal to dmz - Go to top
Top 10 sources

Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.3.1.254 | 26,704,483 | 98.37 | |
| 2 | 10.1.3.50 | 442,752 | 1.63 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.134 | 27,147,235 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.3.1.254 | TCP/443 - ssl-https | 217 | 26,704,483 | 98.37 | |
| 2 | 10.1.3.50 | TCP/443 - ssl-https | 02 | 442,752 | 1.63 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.3.1.254 | 69.49.150.134 | TCP/443 - ssl-https | 217 | 26,704,483 | 98.37 | |
| 2 | 10.1.3.50 | 69.49.150.134 | TCP/443 - ssl-https | 02 | 442,752 | 1.63 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 219 | 27,147,235 | 100.00 |
Firewall: FGT8002604401800 - Interfaces: internal to external - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
Top 10 warning messages
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.3.1.254 | 677,918,920 | 48.93 | |
| 2 | 10.1.1.9 | 344,817,805 | 24.89 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 3 | 10.1.1.47 | 252,343,804 | 18.21 | |
| 4 | 10.1.1.252 | 52,163,811 | 3.76 | |
| 5 | 10.1.1.12 | 14,777,663 | 1.07 | |
| 6 | 10.1.1.251 | 13,732,064 | 0.99 | 5436 denials recorded on 4/4/2006 4:30:22 AM |
| 7 | 10.1.1.52 | 11,904,372 | 0.86 | 3550 denials recorded on 10/31/2006 12:00:11 AM |
| 8 | 10.1.1.240 | 4,183,512 | 0.30 | |
| 9 | 10.1.1.16 | 4,129,580 | 0.30 | 93707 denials recorded on 4/3/2006 11:01:13 PM |
| 10 | 10.1.1.245 | 3,541,836 | 0.26 | 4 denials recorded on 2/28/2006 11:02:42 AM |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 66.98.238.101 | 351,674,291 | 25.38 | |
| 2 | 66.231.220.67 | 252,343,804 | 18.21 | 50 denials recorded on 4/3/2006 11:10:39 PM |
| 3 | 170.146.231.150 | 110,085,055 | 7.95 | |
| 4 | 12.145.177.37 | 56,486,156 | 4.08 | |
| 5 | 66.98.238.102 | 35,882,474 | 2.59 | |
| 6 | 66.220.30.31 | 35,864,697 | 2.59 | |
| 7 | 216.218.202.30 | 27,213,804 | 1.96 | |
| 8 | 66.98.238.114 | 26,603,697 | 1.92 | |
| 9 | 209.132.200.31 | 25,367,479 | 1.83 | |
| 10 | 64.132.202.205 | 20,910,638 | 1.51 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.3.1.254 | TCP/80 - http | 9,875 | 419,843,763 | 30.30 | |
| 2 | 10.1.1.9 | TCP/80 - http | 253 | 344,817,805 | 24.89 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 3 | 10.3.1.254 | TCP/443 - ssl-https | 10,212 | 258,058,596 | 18.62 | |
| 4 | 10.1.1.47 | TCP/110 - pop3 | 90,908 | 239,617,482 | 17.29 | |
| 5 | 10.1.1.252 | TCP/80 - http | 631 | 52,055,374 | 3.76 | |
| 6 | 10.1.1.12 | TCP/21 - ftp | 14 | 14,777,663 | 1.07 | |
| 7 | 10.1.1.251 | TCP/80 - http | 09 | 13,720,309 | 0.99 | 5436 denials recorded on 4/4/2006 4:30:22 AM |
| 8 | 10.1.1.47 | TCP/25 - smtp | 531 | 12,726,322 | 0.92 | |
| 9 | 10.1.1.52 | TCP/443 - ssl-https | 288 | 11,904,372 | 0.86 | 3550 denials recorded on 10/31/2006 12:00:11 AM |
| 10 | 10.1.1.16 | UDP/53 - dns | 71 | 4,126,849 | 0.30 | 93707 denials recorded on 4/3/2006 11:01:13 PM |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.1.1.9 | 66.98.238.101 | TCP/80 - http | 253 | 344,817,805 | 24.89 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 2 | 10.1.1.47 | 66.231.220.67 | TCP/110 - pop3 | 90,908 | 239,617,482 | 17.29 | 50 denials recorded on 4/3/2006 11:10:39 PM |
| 3 | 10.3.1.254 | 170.146.231.150 | TCP/443 - ssl-https | 911 | 108,868,100 | 7.86 | |
| 4 | 10.1.1.252 | 12.145.177.37 | TCP/80 - http | 307 | 47,384,611 | 3.42 | |
| 5 | 10.3.1.254 | 66.98.238.102 | TCP/80 - http | 10 | 35,882,474 | 2.59 | |
| 6 | 10.3.1.254 | 66.220.30.31 | TCP/80 - http | 12 | 35,864,697 | 2.59 | |
| 7 | 10.3.1.254 | 216.218.202.30 | TCP/80 - http | 11 | 27,213,804 | 1.96 | |
| 8 | 10.3.1.254 | 66.98.238.114 | TCP/80 - http | 10 | 26,603,697 | 1.92 | |
| 9 | 10.3.1.254 | 209.132.200.31 | TCP/80 - http | 10 | 25,367,479 | 1.83 | |
| 10 | 10.3.1.254 | 64.132.202.205 | TCP/443 - ssl-https | 856 | 20,910,638 | 1.51 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/80 - http | 10,947 | 835,382,532 | 60.29 | |
| 2 | TCP/443 - ssl-https | 10,525 | 271,470,283 | 19.59 | |
| 3 | TCP/110 - pop3 | 90,908 | 239,617,482 | 17.29 | |
| 4 | TCP/21 - ftp | 25 | 14,824,645 | 1.07 | |
| 5 | TCP/25 - smtp | 531 | 12,726,322 | 0.92 | |
| 6 | UDP/53 - dns | 168 | 4,405,492 | 0.32 | |
| 7 | TCP/3322 | 01 | 2,229,509 | 0.16 | |
| 8 | TCP/2393 | 01 | 1,355,171 | 0.10 | |
| 9 | TCP/2392 | 01 | 1,355,011 | 0.10 | |
| 10 | TCP/2327 | 01 | 1,182,763 | 0.09 |

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.9 | 66.98.238.101 | 253 | 344,817,805 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 2 | 10.1.1.252 | 12.145.177.37 | 307 | 47,384,611 | |
| 3 | 10.3.1.254 | 66.98.238.102 | 10 | 35,882,474 | |
| 4 | 10.3.1.254 | 66.220.30.31 | 12 | 35,864,697 | |
| 5 | 10.3.1.254 | 216.218.202.30 | 11 | 27,213,804 | |
| 6 | 10.3.1.254 | 66.98.238.114 | 10 | 26,603,697 | |
| 7 | 10.3.1.254 | 209.132.200.31 | 10 | 25,367,479 | |
| 8 | 10.3.1.254 | 216.218.211.34 | 14 | 17,341,790 | |
| 9 | 10.1.1.251 | 64.21.46.144 | 05 | 13,712,997 | 5436 denials recorded on 4/4/2006 4:30:22 AM |
| 10 | 10.3.1.254 | 198.151.60.100 | 228 | 10,187,501 | 3 denials recorded on 2/28/2006 11:17:18 AM |
Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.47 | 66.231.220.67 | 531 | 12,726,322 | 50 denials recorded on 4/3/2006 11:10:39 PM |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.52 | 3,550 | 10/31/2006 12:00:11 AM | 21.99 | 3550 denials recorded on 10/31/2006 12:00:11 AM |
| 2 | 10.1.1.232 | 2,182 | 10/31/2006 12:05:01 AM | 13.52 | 2182 denials recorded on 10/31/2006 12:05:01 AM |
| 3 | 10.1.1.9 | 943 | 10/31/2006 12:01:59 AM | 05.84 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 4 | 10.1.1.135 | 516 | 10/31/2006 2:02:47 PM | 03.20 | |
| 5 | 192.168.1.122 | 467 | 10/31/2006 9:53:57 AM | 02.89 | |
| 6 | 10.1.8.103 | 384 | 10/31/2006 2:27:40 AM | 02.38 | |
| 7 | 10.1.1.223 | 350 | 10/31/2006 9:37:29 AM | 02.17 | |
| 8 | 10.1.1.148 | 339 | 10/31/2006 1:27:31 AM | 02.10 | 1137 denials recorded on 4/4/2006 6:38:04 AM |
| 9 | 10.1.1.214 | 306 | 10/31/2006 12:22:00 AM | 01.90 | |
| 10 | 10.1.1.230 | 306 | 10/31/2006 12:31:49 AM | 01.90 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 216.220.225.198 | 3,550 | 10/31/2006 12:00:11 AM | 21.99 | |
| 2 | 12.158.80.10 | 2,255 | 10/31/2006 7:04:28 PM | 13.97 | |
| 3 | 64.94.110.11 | 2,103 | 10/31/2006 7:04:41 PM | 13.03 | |
| 4 | 205.243.60.43 | 1,267 | 10/31/2006 12:37:57 PM | 07.85 | |
| 5 | 205.243.60.42 | 974 | 10/31/2006 12:37:36 PM | 06.03 | |
| 6 | 64.21.46.134 | 846 | 10/31/2006 12:20:42 AM | 05.24 | |
| 7 | 64.21.46.137 | 843 | 10/31/2006 12:21:03 AM | 05.22 | |
| 8 | 69.20.55.137 | 805 | 10/31/2006 12:01:59 AM | 04.99 | |
| 9 | 63.240.63.69 | 449 | 10/31/2006 9:53:57 AM | 02.78 | |
| 10 | 205.243.60.44 | 315 | 10/31/2006 12:40:29 PM | 01.95 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/80 - http | 15,270 | 10/31/2006 12:00:11 AM | 94.60 | |
| 2 | TCP/81 - http | 455 | 10/31/2006 8:54:02 AM | 02.82 | |
| 3 | UDP/137 - netbios | 339 | 10/31/2006 9:37:29 AM | 02.10 | |
| 4 | TCP/443 - ssl-https | 63 | 10/31/2006 1:28:19 AM | 00.39 | |
| 5 | TCP/8080 - http proxy | 06 | 10/31/2006 11:22:07 AM | 00.04 | |
| 6 | TCP/21 - ftp | 03 | 10/31/2006 7:44:07 AM | 00.02 | |
| 7 | TCP/1935 | 03 | 10/31/2006 9:52:28 AM | 00.02 | |
| 8 | TCP/563 | 03 | 10/31/2006 12:00:19 PM | 00.02 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Policy id 61 | 16,142 | 10/31/2006 12:00:11 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 10.1.1.52 | 216.220.225.198 | TCP/80 - http | Policy id 61 | 3,550 | 10/31/2006 12:00:11 AM | 21.99 | 3550 denials recorded on 10/31/2006 12:00:11 AM |
| 2 | 10.1.1.9 | 69.20.55.137 | TCP/80 - http | Policy id 61 | 805 | 10/31/2006 12:01:59 AM | 4.99 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 3 | 192.168.1.122 | 63.240.63.69 | TCP/81 - http | Policy id 61 | 449 | 10/31/2006 9:53:57 AM | 2.78 | |
| 4 | 10.1.1.232 | 205.243.60.43 | TCP/80 - http | Policy id 61 | 288 | 10/31/2006 12:37:57 PM | 1.78 | 2182 denials recorded on 10/31/2006 12:05:01 AM |
| 5 | 10.1.1.232 | 205.243.60.44 | TCP/80 - http | Policy id 61 | 213 | 10/31/2006 12:40:29 PM | 1.32 | |
| 6 | 10.1.1.135 | 205.243.60.43 | TCP/80 - http | Policy id 61 | 159 | 10/31/2006 2:05:53 PM | 0.99 | |
| 7 | 10.1.1.232 | 64.21.46.135 | TCP/80 - http | Policy id 61 | 153 | 10/31/2006 12:44:44 AM | 0.95 | |
| 8 | 10.1.1.232 | 64.21.46.151 | TCP/80 - http | Policy id 61 | 153 | 10/31/2006 12:45:05 AM | 0.95 | |
| 9 | 10.1.1.9 | 64.62.172.18 | TCP/80 - http | Policy id 61 | 138 | 10/31/2006 12:33:21 AM | 0.85 | |
| 10 | 10.1.1.135 | 205.243.60.44 | TCP/80 - http | Policy id 61 | 102 | 10/31/2006 2:09:35 PM | 0.63 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/80 - http | Policy id 61 | 15,270 | 94.60 | |
| 2 | TCP/81 - http | Policy id 61 | 455 | 2.82 | |
| 3 | UDP/137 - netbios | Policy id 61 | 339 | 2.10 | |
| 4 | TCP/443 - ssl-https | Policy id 61 | 63 | 0.39 | |
| 5 | TCP/8080 - http proxy | Policy id 61 | 06 | 0.04 | |
| 6 | TCP/21 - ftp | Policy id 61 | 03 | 0.02 | |
| 7 | TCP/1935 | Policy id 61 | 03 | 0.02 | |
| 8 | TCP/563 | Policy id 61 | 03 | 0.02 |
Top 10 warning messages
| No | Source | Destination | Protocol | Warning | Count | First warning | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 10.1.1.9 | 66.98.238.101 | HTTP | The file kaspersky.zip is infected with Suspicious | 21 | 10/31/2006 2:00:32 AM | 91.30 | 943 denials recorded on 10/31/2006 12:01:59 AM |
| 2 | 10.1.1.47 | 66.231.220.67 | POP3 | The file is infected with HTML/BankFraud.E!phish | 02 | 10/31/2006 8:30:04 PM | 8.70 | 50 denials recorded on 4/3/2006 11:10:39 PM |
Firewall: FGT8002604401800 - Interfaces: internal to port1 - Go to top
Top 10 sources
Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.3.1.254 | 14,213,352 | 100.00 |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 170.209.0.2 | 13,981,443 | 98.37 | |
| 2 | 170.209.0.3 | 231,909 | 1.63 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.3.1.254 | TCP/443 - ssl-https | 947 | 14,213,352 | 100.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.3.1.254 | 170.209.0.2 | TCP/443 - ssl-https | 927 | 13,981,443 | 98.37 | |
| 2 | 10.3.1.254 | 170.209.0.3 | TCP/443 - ssl-https | 20 | 231,909 | 1.63 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 947 | 14,213,352 | 100.00 |
Firewall: FGT8002604401800 - Interfaces: internal to port2 - Go to top
Top 10 sources
Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.1.251 | 15,522,305 | 100.00 | 5436 denials recorded on 4/4/2006 4:30:22 AM |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.146 | 15,522,305 | 100.00 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.1.1.251 | TCP/6129 - agobot-worm | 01 | 14,907,721 | 96.04 | 5436 denials recorded on 4/4/2006 4:30:22 AM |
| 2 | 10.1.1.251 | TCP/3389 - ms rdp | 02 | 614,464 | 3.96 | |
| 3 | 10.1.1.251 | ICMP/8 - ping | 01 | 120 | 0.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.1.1.251 | 69.49.150.146 | TCP/6129 - agobot-worm | 01 | 14,907,721 | 96.04 | 5436 denials recorded on 4/4/2006 4:30:22 AM 5436 denials recorded on 4/4/2006 4:30:22 AM 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | 10.1.1.251 | 69.49.150.146 | TCP/3389 - ms rdp | 02 | 614,464 | 3.96 | |
| 3 | 10.1.1.251 | 69.49.150.146 | ICMP/8 - ping | 01 | 120 | 0.00 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/6129 - agobot-worm | 01 | 14,907,721 | 96.04 | |
| 2 | TCP/3389 - ms rdp | 02 | 614,464 | 3.96 | |
| 3 | ICMP/8 - ping | 01 | 120 | 0.00 |

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.251 | 69.49.150.146 | 02 | 614,464 | 5436 denials recorded on 4/4/2006 4:30:22 AM 5436 denials recorded on 4/4/2006 4:30:22 AM 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.15 | 96 | 10/31/2006 8:53:17 AM | 100.00 | 213 denials recorded on 4/4/2006 7:00:17 AM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 69.49.150.146 | 96 | 10/31/2006 8:53:17 AM | 100.00 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/31239 | 16 | 10/31/2006 3:53:14 PM | 16.67 | |
| 2 | TCP/31130 | 15 | 10/31/2006 2:36:30 PM | 15.63 | |
| 3 | TCP/30599 | 13 | 10/31/2006 9:30:46 AM | 13.54 | |
| 4 | TCP/30919 | 07 | 10/31/2006 12:29:34 PM | 07.29 | |
| 5 | TCP/30920 | 05 | 10/31/2006 12:31:05 PM | 05.21 | |
| 6 | TCP/30724 | 04 | 10/31/2006 10:51:42 AM | 04.17 | |
| 7 | TCP/30738 | 04 | 10/31/2006 10:54:16 AM | 04.17 | |
| 8 | TCP/30740 | 04 | 10/31/2006 10:56:18 AM | 04.17 | |
| 9 | TCP/31151 | 04 | 10/31/2006 2:41:34 PM | 04.17 | |
| 10 | TCP/31241 | 04 | 10/31/2006 3:55:27 PM | 04.17 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | http_decoder: request_smuggling | 95 | 10/31/2006 8:53:17 AM | 98.96 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | http_decoder: request_smuggling, repeated 2 times | 01 | 10/31/2006 12:30:39 PM | 01.04 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/31239 | http_decoder: request_smuggling | 16 | 16.67 | |
| 2 | TCP/31130 | http_decoder: request_smuggling | 15 | 15.63 | |
| 3 | TCP/30599 | http_decoder: request_smuggling | 13 | 13.54 | |
| 4 | TCP/30919 | http_decoder: request_smuggling | 06 | 6.25 | |
| 5 | TCP/30920 | http_decoder: request_smuggling | 05 | 5.21 | |
| 6 | TCP/30724 | http_decoder: request_smuggling | 04 | 4.17 | |
| 7 | TCP/30738 | http_decoder: request_smuggling | 04 | 4.17 | |
| 8 | TCP/30740 | http_decoder: request_smuggling | 04 | 4.17 | |
| 9 | TCP/31151 | http_decoder: request_smuggling | 04 | 4.17 | |
| 10 | TCP/31241 | http_decoder: request_smuggling | 04 | 4.17 |
Firewall: FGT8002604401800 - Interfaces: N/A to external - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 63.75.200.25 | 18,084,274 | 91.59 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 192.63.69.253 | 1,623,380 | 8.22 | |
| 3 | 63.75.200.20 | 37,373 | 0.19 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.10 | 19,707,654 | 99.81 | |
| 2 | 69.49.150.129 | 37,373 | 0.19 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 63.75.200.25 | TCP/443 - ssl-https | 1,241 | 18,084,274 | 91.59 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 192.63.69.253 | TCP/443 - ssl-https | 66 | 1,623,380 | 8.22 | |
| 3 | 63.75.200.20 | ICMP/8 - ping | 287 | 26,292 | 0.13 | |
| 4 | 63.75.200.20 | UDP/161 - snmp | 07 | 11,081 | 0.06 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 63.75.200.25 | 69.49.150.10 | TCP/443 - ssl-https | 1,241 | 18,084,274 | 91.59 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 192.63.69.253 | 69.49.150.10 | TCP/443 - ssl-https | 66 | 1,623,380 | 8.22 | |
| 3 | 63.75.200.20 | 69.49.150.129 | ICMP/8 - ping | 287 | 26,292 | 0.13 | |
| 4 | 63.75.200.20 | 69.49.150.129 | UDP/161 - snmp | 07 | 11,081 | 0.06 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 1,307 | 19,707,654 | 99.81 | |
| 2 | ICMP/8 - ping | 287 | 26,292 | 0.13 | |
| 3 | UDP/161 - snmp | 07 | 11,081 | 0.06 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 63.75.200.25 | 1,853 | 10/31/2006 12:01:10 AM | 99.78 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 69.39.70.231 | 03 | 10/31/2006 6:30:40 PM | 00.16 | 3 denials recorded on 10/31/2006 6:30:40 PM |
| 3 | 61.190.208.3 | 01 | 10/31/2006 2:08:00 PM | 00.05 | 1 denials recorded on 10/31/2006 2:08:00 PM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 69.49.150.10 | 1,857 | 10/31/2006 12:01:10 AM | 100.00 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/22 - ssh | 1,854 | 10/31/2006 12:01:10 AM | 99.84 | |
| 2 | TCP/80 - http | 03 | 10/31/2006 6:30:40 PM | 00.16 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Policy id 0 | 1,857 | 10/31/2006 12:01:10 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 63.75.200.25 | 69.49.150.10 | TCP/22 - ssh | Policy id 0 | 1,853 | 10/31/2006 12:01:10 AM | 99.78 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 69.39.70.231 | 69.49.150.10 | TCP/80 - http | Policy id 0 | 03 | 10/31/2006 6:30:40 PM | 0.16 | 3 denials recorded on 10/31/2006 6:30:40 PM |
| 3 | 61.190.208.3 | 69.49.150.10 | TCP/22 - ssh | Policy id 0 | 01 | 10/31/2006 2:08:00 PM | 0.05 | 1 denials recorded on 10/31/2006 2:08:00 PM |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/22 - ssh | Policy id 0 | 1,854 | 99.84 | |
| 2 | TCP/80 - http | Policy id 0 | 03 | 0.16 |
Firewall: FGT8002604401800 - Interfaces: port1 to external - Go to top
Top 10 sources
Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.154 | 18,368,408 | 100.00 |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 199.169.223.10 | 17,263,320 | 93.98 | |
| 2 | 63.240.132.101 | 1,105,088 | 6.02 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 69.49.150.154 | OTHER | 14 | 16,999,784 | 92.55 | |
| 2 | 69.49.150.154 | ICMP/8 - ping | 01 | 1,105,088 | 6.02 | |
| 3 | 69.49.150.154 | UDP/500 - ipsec | 21 | 263,536 | 1.43 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.154 | 199.169.223.10 | OTHER | 14 | 16,999,784 | 92.55 | |
| 2 | 69.49.150.154 | 63.240.132.101 | ICMP/8 - ping | 01 | 1,105,088 | 6.02 | |
| 3 | 69.49.150.154 | 199.169.223.10 | UDP/500 - ipsec | 21 | 263,536 | 1.43 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | OTHER | 14 | 16,999,784 | 92.55 | |
| 2 | ICMP/8 - ping | 01 | 1,105,088 | 6.02 | |
| 3 | UDP/500 - ipsec | 21 | 263,536 | 1.43 |

Firewall: FGT8002604401800 - Interfaces: port2 to internal - Go to top
Top 10 sources
Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 69.49.150.146 | 35,643,766 | 100.00 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.1.18 | 19,095,152 | 53.57 | 241026 denials recorded on 4/3/2006 11:01:03 PM |
| 2 | 10.1.1.15 | 16,503,704 | 46.30 | 213 denials recorded on 4/4/2006 7:00:17 AM |
| 3 | 10.1.1.12 | 44,910 | 0.13 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 69.49.150.146 | TCP/80 - http | 63 | 16,503,704 | 46.30 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | 69.49.150.146 | TCP/389 - ldap | 526 | 14,096,302 | 39.55 | |
| 3 | 69.49.150.146 | TCP/3268 | 111 | 1,984,936 | 5.57 | |
| 4 | 69.49.150.146 | TCP/445 - netbios | 191 | 1,402,361 | 3.93 | |
| 5 | 69.49.150.146 | UDP/88 - kerberos | 419 | 1,056,203 | 2.96 | |
| 6 | 69.49.150.146 | TCP/53 - dns | 190 | 316,914 | 0.89 | |
| 7 | 69.49.150.146 | TCP/1027 - icq | 20 | 79,143 | 0.22 | |
| 8 | 69.49.150.146 | UDP/389 - ldap | 126 | 50,261 | 0.14 | |
| 9 | 69.49.150.146 | UDP/514 - syslog | 126 | 44,910 | 0.13 | |
| 10 | 69.49.150.146 | TCP/88 - kerberos | 12 | 43,000 | 0.12 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.146 | 10.1.1.15 | TCP/80 - http | 63 | 16,503,704 | 46.30 | 213 denials recorded on 4/4/2006 7:00:17 AM 213 denials recorded on 4/4/2006 7:00:17 AM 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | 69.49.150.146 | 10.1.1.18 | TCP/389 - ldap | 526 | 14,096,302 | 39.55 | 241026 denials recorded on 4/3/2006 11:01:03 PM |
| 3 | 69.49.150.146 | 10.1.1.18 | TCP/3268 | 111 | 1,984,936 | 5.57 | |
| 4 | 69.49.150.146 | 10.1.1.18 | TCP/445 - netbios | 191 | 1,402,361 | 3.93 | |
| 5 | 69.49.150.146 | 10.1.1.18 | UDP/88 - kerberos | 419 | 1,056,203 | 2.96 | |
| 6 | 69.49.150.146 | 10.1.1.18 | TCP/53 - dns | 190 | 316,914 | 0.89 | |
| 7 | 69.49.150.146 | 10.1.1.18 | TCP/1027 - icq | 20 | 79,143 | 0.22 | |
| 8 | 69.49.150.146 | 10.1.1.18 | UDP/389 - ldap | 126 | 50,261 | 0.14 | |
| 9 | 69.49.150.146 | 10.1.1.12 | UDP/514 - syslog | 126 | 44,910 | 0.13 | |
| 10 | 69.49.150.146 | 10.1.1.18 | TCP/88 - kerberos | 12 | 43,000 | 0.12 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/80 - http | 63 | 16,503,704 | 46.30 | |
| 2 | TCP/389 - ldap | 526 | 14,096,302 | 39.55 | |
| 3 | TCP/3268 | 111 | 1,984,936 | 5.57 | |
| 4 | TCP/445 - netbios | 191 | 1,402,361 | 3.93 | |
| 5 | UDP/88 - kerberos | 419 | 1,056,203 | 2.96 | |
| 6 | TCP/53 - dns | 190 | 316,914 | 0.89 | |
| 7 | TCP/1027 - icq | 20 | 79,143 | 0.22 | |
| 8 | UDP/389 - ldap | 126 | 50,261 | 0.14 | |
| 9 | UDP/514 - syslog | 126 | 44,910 | 0.13 | |
| 10 | TCP/88 - kerberos | 12 | 43,000 | 0.12 |

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 69.49.150.146 | 10.1.1.15 | 63 | 16,503,704 | 213 denials recorded on 4/4/2006 7:00:17 AM 213 denials recorded on 4/4/2006 7:00:17 AM 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 69.49.150.146 | 1,480 | 10/31/2006 12:00:27 AM | 100.00 | 1455 denials recorded on 10/31/2006 12:00:27 AM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.1.18 | 866 | 10/31/2006 12:00:27 AM | 58.51 | 241026 denials recorded on 4/3/2006 11:01:03 PM |
| 2 | 10.1.1.16 | 133 | 10/31/2006 12:14:11 AM | 08.99 | 93707 denials recorded on 4/3/2006 11:01:13 PM |
| 3 | 10.1.1.15 | 25 | 10/31/2006 9:30:47 AM | 01.69 | 213 denials recorded on 4/4/2006 7:00:17 AM |
| 4 | 192.168.7.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | |
| 5 | 10.1.6.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | 2 denials recorded on 3/24/2006 5:37:42 AM |
| 6 | 10.1.7.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | 261 denials recorded on 4/3/2006 11:01:18 PM |
| 7 | 10.1.4.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | 13802 denials recorded on 3/24/2006 5:43:56 AM |
| 8 | 10.1.2.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 9 | 192.168.3.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 | |
| 10 | 10.1.3.3 | 24 | 10/31/2006 12:14:19 AM | 01.62 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/8 - ping | 866 | 10/31/2006 12:00:27 AM | 58.51 | |
| 2 | UDP/138 - netbios | 528 | 10/31/2006 12:14:11 AM | 35.68 | |
| 3 | UDP/389 - ldap | 61 | 10/31/2006 12:14:11 AM | 04.12 | |
| 4 | HTTP | 25 | 10/31/2006 9:30:47 AM | 01.69 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Policy id 94 | 1,455 | 10/31/2006 12:00:27 AM | 98.31 | |
| 2 | http_decoder: request_smuggling | 24 | 10/31/2006 9:30:47 AM | 01.62 | |
| 3 | web_server: IIS.Translate.F.Disclose | 01 | 10/31/2006 12:30:26 PM | 00.07 |

Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.146 | 10.1.1.18 | ICMP/8 - ping | Policy id 94 | 866 | 10/31/2006 12:00:27 AM | 58.51 | 241026 denials recorded on 4/3/2006 11:01:03 PM 241026 denials recorded on 4/3/2006 11:01:03 PM 1455 denials recorded on 10/31/2006 12:00:27 AM |
| 2 | 69.49.150.146 | 10.1.1.16 | UDP/138 - netbios | Policy id 94 | 72 | 10/31/2006 12:14:11 AM | 4.86 | 93707 denials recorded on 4/3/2006 11:01:13 PM |
| 3 | 69.49.150.146 | 10.1.1.16 | UDP/389 - ldap | Policy id 94 | 61 | 10/31/2006 12:14:11 AM | 4.12 | |
| 4 | 69.49.150.146 | 192.168.7.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | |
| 5 | 69.49.150.146 | 10.1.6.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | 2 denials recorded on 3/24/2006 5:37:42 AM |
| 6 | 69.49.150.146 | 10.1.7.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | 261 denials recorded on 4/3/2006 11:01:18 PM |
| 7 | 69.49.150.146 | 10.1.4.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | 13802 denials recorded on 3/24/2006 5:43:56 AM |
| 8 | 69.49.150.146 | 10.1.2.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 9 | 69.49.150.146 | 192.168.3.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 | |
| 10 | 69.49.150.146 | 10.1.3.3 | UDP/138 - netbios | Policy id 94 | 24 | 10/31/2006 12:14:19 AM | 1.62 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/8 - ping | Policy id 94 | 866 | 58.51 | |
| 2 | UDP/138 - netbios | Policy id 94 | 528 | 35.68 | |
| 3 | UDP/389 - ldap | Policy id 94 | 61 | 4.12 | |
| 4 | HTTP | http_decoder: request_smuggling | 24 | 1.62 | |
| 5 | HTTP | web_server: IIS.Translate.F.Disclose | 01 | 0.07 |
Firewall: FGT8002604401800 - Interfaces: Not specified - Go to top
Top 10 warning messages
| No | Source | Destination | Protocol | Warning | Count | First warning | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 63.75.200.25 | FGT8002604401800 | GUI | User admin login successfully from GUI(63.75.200.25) | 03 | 10/31/2006 6:49:06 AM | 37.50 | 1853 denials recorded on 10/31/2006 12:01:10 AM |
| 2 | 192.63.69.253 | FGT8002604401800 | GUI | User admin login successfully from GUI(192.63.69.253) | 03 | 10/31/2006 8:17:35 AM | 37.50 | |
| 3 | 10.1.1.252 | FGT8002604401800 | GUI | User nsnm-ro login successfully from GUI(10.1.1.252) | 01 | 10/31/2006 9:28:44 AM | 12.50 | |
| 4 | 10.1.1.252 | FGT8002604401800 | SSH | User nsnm-ro login successfully from SSH(10.1.1.252) | 01 | 10/31/2006 9:44:01 AM | 12.50 |
Firewall: FGT8002604401800 - Interfaces: n/a to external - Go to top
Top 10 warning messages
| No | Source | Destination | Protocol | Warning | Count | First warning | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.10 | 63.77.242.162 | IPSEC | VPN Tunnel: SCC-Primary - Negotiate SA Error: Peer's id payloads do not match local policy. | 556 | 10/31/2006 12:02:25 AM | 100.00 |
Firewall: FGT8002604401800 - Interfaces: if to - Go to top
Top 10 VPN users
Top 10 LAN-to-LAN VPNs
| No | Source | User | Conns | First conn | Last conn | Comment |
|---|
Top 10 LAN-to-LAN VPNs
| No | Source | Destination | Protocol | Conns | First conn | Last conn | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.10 | 63.77.242.174 | IPSEC | 102 | 10/31/2006 12:14:58 AM | 10/31/2006 11:25:33 PM |
Firewall: FGT8002604401800 - Interfaces: if to external - Go to top
Top 10 VPN users
Top 10 LAN-to-LAN VPNs

| No | Source | User | Conns | First conn | Last conn | Comment |
|---|
Top 10 LAN-to-LAN VPNs
| No | Source | Destination | Protocol | Conns | First conn | Last conn | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 69.49.150.10 | 63.77.242.162 | IPSEC | 1490 | 10/31/2006 12:02:25 AM | 10/31/2006 11:59:16 PM | |
| 2 | 69.49.150.10 | 24.97.162.254 | IPSEC | 305 | 10/31/2006 12:01:29 AM | 10/31/2006 11:59:44 PM | |
| 3 | 69.49.150.10 | 207.190.247.1 | IPSEC | 12 | 10/31/2006 6:26:52 AM | 10/31/2006 10:16:52 PM |

| No | Code | Message sample | Count | Comment |
|---|
Analysis details
| Analysis start time | 11/15/2011 6:46:12 PM |
| Analysis duration | 0.39 minutes (23 seconds) |
| Analysis engine version | Fortigate parser version: 0.04 FireGen30Service.exe - FireGen scheduler service: 3.0.0.0 |
| Filtering criteria | All entries |
| Excluded keywords | None |
Glossary
| !!! | Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface. |
| Other messages | The Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer. |